Skip to content
Academy · Cybersecurity · intermediate

HIGAET Identity & Access Security

Learn identity-first defense and build MFA rollouts, lifecycle workflows, privileged access reviews, and directory monitoring in practice labs.

Duration

6 weeks · 8-10 hours/week

Level

Intermediate

Delivery

Online

Status

Open for enrollment

Introduction

Why this technology matters.

Identity and access security is the identity-first approach to defense: making sure the right people and systems can reach the right resources — and nothing else. It matters now because stolen credentials and overbroad access are among the most common paths into an organization. This course teaches the lifecycle habits that keep access correct over time, in practice labs.

You will use these controls in IT and security teams: directory structures with groups and roles, MFA and conditional access policies, and joiner-mover-leaver workflows with approval trails. This solves access sprawl and lingering privileges that accumulate as people change roles. It does not solve everything: MFA does not fix unmanaged devices on its own, reviews do not fix unclear role definitions, and policies do not fix processes nobody follows.

By the end you will be able to build a directory structure with groups, roles, and naming standards, an MFA and conditional access policy set for a lab tenant, and a joiner-mover-leaver workflow with privileged access reviews and just-in-time controls.

Why this course exists

The gap is between creating accounts once and keeping access correct as people join, move, and leave. This course closes it with an arc from structure to policy to lifecycle to review: organize directories and roles, enforce MFA and conditional access, run lifecycle workflows with approvals, then review privileged access on a repeatable cycle.

Overview

Know exactly what you're signing up for.

Who is this for

IT administratorsSecurity practitionersOperations staffCloud engineersEngineering managers

Prerequisites

  • No previous identity security experience required
  • Basic directory and user account familiarity
  • Comfort with admin consoles and policies

Technologies & tools

Directory servicesGroup and role designMFA policiesConditional access rulesLifecycle workflowsPrivileged access reviewsJust-in-time controls

Skills you'll gain

Directory designRole modelingMFA rolloutConditional accessLifecycle workflowsPrivileged access reviewDirectory monitoring
Curriculum

A 6 weeks arc, module by module.

  1. Module 01

    Module 01 — Foundations: Identity models and access principles

  2. Module 02

    Module 02 — Directories: Users, groups, and role design

  3. Module 03

    Module 03 — Authentication: MFA and conditional access

  4. Module 04

    Module 04 — Core: Lifecycle workflows and approvals

  5. Module 05

    Module 05 — Privilege: Reviews, vaulting, and session controls

  6. Module 06

    Module 06 — Capstone: Identity-hardened lab with review report

Practical Training Flow

Learning → Guided Labs → Independent Practice → Industry Project → Capstone → Portfolio → Career Preparation. Practical hours are tracked alongside instructional hours and surfaced on the certificate.

Delivery as HIGAET Practical Training / Experiential Learning.

identity securityiammfaconditional accessprivileged accessaccess reviewsingle sign ondirectory defensehigaet academy
Outcomes

What you'll be able to do.

  • Build directory structures with groups, roles, and naming standards
  • Design MFA and conditional access policies for lab tenants
  • Develop joiner-mover-leaver workflows with approval trails
  • Deploy privileged access reviews and just-in-time controls
  • Integrate single sign-on for sample lab applications
  • Evaluate access logs for anomalous sign-in patterns
  • Secure service accounts and API credentials defensively
  • Automate access review reminders and evidence exports
Projects

You will build.

Every project ships as HIGAET Practical Training / Experiential Learning — portfolio-ready work, not exercises.

  1. Project 01

    Directory structure with roles and standards

  2. Project 02

    MFA and conditional access policy set

  3. Project 03

    Joiner-mover-leaver workflow with approvals

  4. Capstone

    Identity-first defense with lifecycle workflows, MFA policies, and privileged access reviews

Key concepts

Speak the language first.

Directory structure
Organized groups, roles, and naming standards that make user and system accounts easy to manage.
Least privilege
Giving each account only the permissions it needs so a compromised account causes less harm.
Multi-factor authentication (MFA)
Requiring two or more proofs of identity, such as a password plus a phone code, at sign-in.
Conditional access
Policies that allow or challenge sign-ins based on conditions like device, location, or risk level.
Joiner-mover-leaver workflow
Standard steps for creating, updating, and removing access as people join, change roles, or leave.
Approval trails
Recorded requests and approvals for access changes that show who authorized what and when.
Privileged access review
Periodic checks of high-power accounts to confirm each one is still needed and correctly scoped.
Just-in-time access
Granting elevated permissions only for a short approved window instead of permanently.
Directory monitoring
Watching sign-in and change logs for unusual identity activity such as mass permission grants.
Keep going

Fix, check, and go deeper.

Troubleshooting & common mistakes

MFA rollout locks out legitimate lab users

Check enrollment status and fallback methods, confirm time sync on authenticator apps, and provide temporary verified bypass with an expiry.

Conditional access policy blocks an entire lab group

Review policy conditions and assignments in audit logs, narrow the scope to the intended group, and test with a pilot account first.

Leaver accounts retain access after departure

Audit HR or roster feeds against the directory, disable orphaned accounts, and fix the workflow trigger that missed the event.

Privilege review flags too many stale admin accounts

Sort by last use and owner, remove or downgrade confirmed-stale accounts, and set shorter review cycles for remaining privileged roles.

Just-in-time elevation never expires

Inspect the time-bound policy and approval ticket linkage, correct the duration setting, and revoke lingering active elevations.

Before you move on, you should be able to

  • Build directory structures with groups, roles, and naming standards
  • Design MFA and conditional access policies for lab tenants
  • Develop joiner-mover-leaver workflows with approval trails
  • Deploy privileged access reviews and just-in-time controls
  • Explain how least privilege reduces identity risk
  • Evaluate directory monitoring logs for unusual access activity
Apply

Start your application.

Share a few details and a HIGAET advisor will reach out within one business day with next steps.

FAQ

Common questions

Ready to start HIGAET Identity & Access Security?

A 6 weeks course — Cybersecurity.